Still have questions?
Speak to our team
For an FCA regulated investment firm, judging the performance of an IT provider can be surprisingly difficult.
If employees can access their systems, emails are working and support requests are being resolved, it is tempting to assume everything is fine.
But good IT management goes much further than fixing problems.
Your provider may have privileged access to some of your most sensitive systems and data. They may be responsible for protecting Microsoft 365, managing devices, monitoring cyber threats and helping you demonstrate appropriate technology governance.
They should also be helping your business improve.
So how can you tell whether your IT provider is genuinely doing a good job?

Here are 10 questions we believe every investment firm should be able to answer.
Resolving IT problems quickly is important, but the better question is how many of those problems could have been prevented.
Recurring issues are often a sign that the underlying cause is not being addressed.
A good IT provider should analyse problems, identify patterns and make improvements that reduce the likelihood of them happening again.
Over time, you should see fewer problems, not simply faster responses to them.
Your IT provider telling you that everything looks good is not particularly useful.
Ask them to show you.
There should be a defined standard against which your environment is regularly assessed. This should cover areas such as Microsoft 365 configuration, identity, devices, data protection, resilience, governance and cyber security.
Those standards should also evolve as guidance from organisations such as the FCA, NCSC and technology providers changes.
If there is no benchmark, how does anyone know what good looks like?
Cyber security should be built into your IT service rather than treated as a collection of optional extras.
More importantly, your provider should be able to demonstrate that the controls they manage are working.
For example, can they show:
Evidence is far more valuable than reassurance.
An investment firm’s IT provider does not replace its compliance advisers, nor should it provide regulatory advice outside its expertise.
However, it should understand the environment in which an FCA regulated business operates.
That means keeping up with relevant changes in areas such as operational resilience, cyber security, data governance, outsourcing, third party risk and AI.
When regulatory or industry expectations change, your provider should be considering what those changes mean for the technology they manage.
You should not always have to bring the changes to them.
Managing partners and directors do not need a 40 page technical report filled with alerts and statistics.
They need to understand the risks that matter.
A good IT provider should be able to explain:
Where a risk cannot immediately be resolved, it should remain visible rather than disappearing into an IT support system.
Good IT governance gives leadership clarity.
Your IT provider is not simply another supplier.
Depending on how your technology is managed, their team may have administrative access to Microsoft 365, devices, security platforms, backups and other critical systems.
That makes the security of your IT provider particularly important.
Ask how they protect privileged access, how administrative credentials are managed, how their employees are vetted and trained, and what happens when somebody leaves their business.
You should also understand what security accreditations they maintain and how they monitor their own environment for compromise.
An IT provider should be comfortable answering difficult questions about its own security.
Technology does not remain static.
Microsoft changes its platforms. New vulnerabilities appear. Employees join and leave. New applications are introduced. Working practices change.
An environment that met best practice two years ago may not meet it today.
This is why we believe IT should operate as a continuous improvement process.
The environment should be regularly audited against an agreed standard, gaps should be identified, improvements agreed and progress measured.
A useful question to ask your provider is:
What is demonstrably better about our IT today than it was 12 months ago?
They should be able to give you a specific answer.
Keeping your existing technology running is only part of the job.
A strategic IT provider should also help you understand where new technology can improve the business.
AI is an obvious example.
Investment firms are exploring how AI can improve research, reporting, administration, meeting preparation and internal processes. But there are also questions around confidentiality, governance, accuracy and appropriate use.
Your IT provider should be helping leadership evaluate these opportunities and implement the right technology safely.
The conversation should be about business value, not simply which licences you can buy.
Your operational IT should already be secure, resilient and properly maintained.
A roadmap is about what comes next.
It should start with your business objectives and consider how technology can support growth, improve productivity, respond to industry change and create competitive advantage.
For example, if the business plans to increase assets under management, launch a new investment strategy, recruit another team or improve operational efficiency, what technology changes could support those objectives?
Your provider should understand where your business is going and translate those objectives into a practical technology plan.
This is perhaps the simplest test of all.
If your provider says your IT is improving, what evidence supports that statement?
At Pro Drive IT, our Pro Drive 360 approach assesses more than 200 operational, security and productivity factors.
This provides a benchmark that can be revisited so improvements can be measured rather than assumed.
The process follows four stages:
Audit. Roadmap. Align. Enforce.
The objective is not to achieve a perfect score and forget about it. Technology, threats and business requirements will continue to change.
The objective is to create a structured process that keeps your technology moving in the right direction.
If you want a quick way to assess your current provider, ask these five questions at your next meeting:
The quality of the answers should tell you a great deal about the relationship you have with your provider.
For an FCA regulated investment firm, keeping systems running should be the minimum expectation.
A good technology partner should also help you understand risk, demonstrate good governance, maintain your environment against defined standards and continually improve it.
Beyond that operational foundation, they should understand your business strategy and help you use technology to improve productivity, embrace developments such as AI and prepare for changes within the investment sector.
At Pro Drive IT, this is the principle behind Pro Drive 360.
We believe investment firms should be able to see how their technology is performing, understand where improvement is required and have confidence that their IT is getting better over time.
Because the real measure of an IT provider is not how busy their helpdesk is. It is the business outcomes their approach delivers.
To learn more about how Pro Drive 360 enforces the standards that FCA regulated investments firms need to meet, book an IT review meeting with us now.
Speak to our team